Clover Health Faces Four Class-Action Lawsuits Over Breach - clover health lawsuit
Clover Health Faces Four Class-Action Lawsuits Over Breach

Clover Health is facing four proposed class-action lawsuits over a cybersecurity incident that potentially exposed members’ personal and protected health information. The complaints were filed between July 22 and July 24 in the U.S. District Court for the Middle District of Tennessee, according to the company’s second-quarter financial filing.

Plaintiffs Allege Negligence, Other Claims

The first lawsuit, Christian et al. v. Clover Health Investments, was filed July 22 by Gregory Christian, Sharon Cox and Barbara Palermo. Clyde Homan and Thomas Griffin filed two separate complaints July 23, followed by a fourth lawsuit from Kenneth Karwoski on July 24.

The complaints allege negligence, unjust enrichment, breach of implied contract and other common-law claims stemming from the alleged compromise of personally identifiable information and protected health information. Clover said in its Q2 financial filing that it intends to “vigorously defend these matters.” The company said the lawsuits are in their early stages, and it cannot reasonably estimate its potential losses.

Related: HCA adjusts earnings due to higher uninsured patient count

How the Breach Occurred

The insurer disclosed the cybersecurity incident on July 17 after detecting unusual login activity on some of its information systems July 4. An investigation involving third-party cybersecurity experts found that a threat actor used social engineering to gain access to three nonmanagerial health plan employee accounts. The employees worked in member visit scheduling and broker-facing sales.

The accounts could access certain personally identifiable information and protected health information, but they could not access Clover’s corporate financial or claims systems, the company said in an SEC filing from July. Clover said it believes it contained and ended the unauthorized access. It also notified law enforcement and began strengthening its information technology environment.

The insurer has not publicly disclosed how many members were affected or precisely what information was viewed or acquired. Clover said it will notify affected members as required after determining the scope of the incident. With 157,309 Medicare Advantage members as of June 30, representing a 48% increase from the prior year, the potential scope of exposure remains unclear pending the investigation’s conclusion.

Related: New Alzheimer’s drug safety under scrutiny

Legal battles over data security are escalating. Plaintiffs in the Clover cases are seeking damages for the alleged negligence. They argue the incident violated privacy rights and resulted in financial harm. The defendants maintain that they took immediate steps to mitigate the damage once detected.

Financial figures show a mixed picture for the company. Clover reported second-quarter net income of $28 million and $443 million in cash, cash equivalents and investments. Management stated that the incident did not appear to have a material impact on business operations or financial results.

Industry Context

The disclosure came amid continued attacks targeting healthcare organizations and the sensitive information they maintain. Yale New Haven Health faced two federal lawsuits after reporting a 2025 data breach affecting more than 5.5 million people. Ascension also faced class-action litigation following its Black Basta ransomware attack, while 39 healthcare providers sued UnitedHealth Group over the financial and operational fallout from the Change Healthcare cyberattack. Healthcare cyberattacks can cost as much as $11 million per breach, according to a 2023 analysis.